216.73.217.22

APT24 Pivot to Multi-Vector Attacks

· Published 20/11/2025 19:42 · Modified 21/11/2025 15:02

Export JSON

Essential information

Published
20/11/2025 19:42
Modified
21/11/2025 15:02
Tags
2025-11-20 badaudio china cobalt strike cobalt strike beacon cyber espionage obfuscation phishing strategic web compromise supply-chain
Related entities
1 intrusion sets (apt), 8 techniques (mitre), 3 others

Description

APT24, a Chinese threat actor, has conducted a three-year campaign using , a highly obfuscated first-stage downloader. The group has evolved from broad strategic web compromises to more sophisticated tactics, including supply chain attacks and targeted . They compromised a Taiwanese digital marketing firm, affecting over 1,000 domains. APT24 uses advanced techniques like control flow flattening, fingerprinting, and covert data exfiltration. The malware integrates with and employs DLL Search Order Hijacking for execution. The campaign demonstrates the actor's persistent and adaptive capabilities, highlighting the growing sophistication of Chinese cyber threats.

External references